CVE-2026-100693: 
NixOS Análise e mitigação de vulnerabilidades

Visão geral

CVE-2026-100693 is a Server-Side Request Forgery (SSRF) / security restriction bypass vulnerability in the Hugo static site generator, caused by improper handling of case sensitivity in the security.http.urls IP-literal deny rule. Attackers can supply mixed-case URL schemes (e.g., HTTP://127.0.0.1/) in resources.GetRemote calls to bypass the deny rule and fetch content from restricted IP addresses such as localhost. The vulnerability affects Hugo versions v0.162.0 through v0.165.x (before v0.166.0) and was publicly disclosed on September 26, 2026. It carries a CVSS v3.1 base score of 8.4 (High) and a CVSS v4.0 base score of 8.6 (High) (GitHub Advisory, Hugo Security Advisory).

Detalhes técnicos

The root cause is classified as CWE-178 (Improper Handling of Case Sensitivity) and CWE-918 (Server-Side Request Forgery). Hugo's security.http.urls allowlist is the sole control governing outbound HTTP fetches made by the resources.GetRemote function; the default IP-literal deny rule performed a case-sensitive comparison, meaning that an uppercase or mixed-case scheme such as HTTP://127.0.0.1/ or Http://localhost/ bypassed the restriction while other default rules were already case-insensitive (Hugo Security Advisory). The attack vector is local (an attacker must be able to influence Hugo template content or configuration), requires no privileges, and has low attack complexity (GitHub Advisory). The vulnerability was discovered by researcher Reload3d and reported to the Hugo project (Hugo Security Advisory).

Impacto

Successful exploitation allows an unauthenticated local user (or any party able to supply untrusted URLs to resources.GetRemote) to access restricted network resources such as localhost services, internal APIs, or metadata endpoints that the IP-literal deny rule was intended to block. The CVSS scoring reflects high confidentiality, integrity, and availability impact on the vulnerable system, meaning an attacker could read sensitive local data, potentially manipulate content fetched during site builds, or disrupt the build process (GitHub Advisory, Red Hat Bugzilla). The scope is limited to the vulnerable Hugo build environment and does not propagate to subsequent systems.

Exploração

As of the time of disclosure, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (GitHub Advisory). The NVD SSVC assessment confirms exploitation status as "none" and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.13% (3rd percentile), indicating a low near-term exploitation probability. Exploitation requires local access or the ability to influence Hugo template/configuration content, which limits the attacker pool.

Etapas de exploração

  1. Identify a target Hugo build environment: Confirm the Hugo version is between v0.162.0 and v0.165.x and that resources.GetRemote is used in templates or shortcodes with attacker-influenced URL input.
  2. Craft a mixed-case URL scheme: Prepare a URL targeting a restricted IP address using an uppercase or mixed-case scheme, e.g., HTTP://127.0.0.1:8080/internal-api or Http://localhost/admin.
  3. Inject the URL into a resources.GetRemote call: Supply the crafted URL as input to a Hugo template that passes it to resources.GetRemote, either by modifying a content file, shortcode parameter, or configuration that feeds into the template.
  4. Trigger a Hugo build: Cause the Hugo site to be built (e.g., by running hugo or triggering a CI/CD pipeline), which will invoke resources.GetRemote with the crafted URL.
  5. Bypass the IP-literal deny rule: The case-sensitive deny rule fails to match the mixed-case scheme, allowing the fetch to proceed to the restricted IP address.
  6. Retrieve restricted content: The response from the internal service is fetched and may be embedded in the generated site output or accessible to the attacker, exposing sensitive internal data (Hugo Security Advisory, GitHub Advisory).

Indicadores de compromisso

  • Logs: Hugo build logs containing resources.GetRemote calls with mixed-case URL schemes (e.g., HTTP://, Http://, HTTPS://) targeting loopback or private IP ranges (127.0.0.0/8, 169.254.0.0/16, 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16).
  • Network: Outbound HTTP/HTTPS connections from the Hugo build process to localhost or internal network addresses during site generation; unexpected connections to metadata endpoints (e.g., 169.254.169.254 for cloud instance metadata).
  • File System: Generated site output files containing unexpected content sourced from internal services or localhost endpoints, embedded as Hugo page resources or data files.
  • Process: Hugo process making network connections to loopback or RFC-1918 addresses during build execution, observable via network monitoring tools (e.g., netstat, ss, or EDR telemetry).

Mitigação e soluções alternativas

Upgrade Hugo to version v0.166.0 or later, which fixes the IP-literal deny rule to perform case-insensitive scheme matching (Hugo Security Advisory). As an interim workaround, avoid passing untrusted or user-controlled URLs to resources.GetRemote, or replace the default deny-list approach with an explicit allow-list of trusted hosts in security.http.urls (Hugo Security Advisory). Organizations using Hugo in CI/CD pipelines should audit template and shortcode inputs for externally influenced URL parameters.

Reações da comunidade

The vulnerability was noted on Mastodon by The Hacker Wire shortly after disclosure, and was tracked by standard vulnerability aggregators including VulnDB, CVEFeed, and OSV (GitHub Advisory). Red Hat opened a Bugzilla entry and assigned medium severity, reflecting the local attack vector constraint (Red Hat Bugzilla). No significant broader media coverage or notable researcher commentary beyond the initial advisory has been observed.

Recursos adicionais

Status correto da distribuição Linux

Disponibilidade de correção em distribuições Linux principais e suas versões.

Debian

Fixo

bookworm

hugo

Fixo

sid

hugo: 0.166.0-1

Fixo

trixie

hugo

Fixo

Ubuntu

Desconhecido

bionic (esm-apps)

hugo

Desconhecido

devel

hugo

Desconhecido

focal (esm-apps)

hugo

Desconhecido

jammy

hugo

Desconhecido

jammy (esm-apps)

hugo

Desconhecido

noble

hugo

Desconhecido

noble (esm-apps)

hugo

Desconhecido

resolute

hugo

Desconhecido

RHEL / CentOS

Afetados

RHEL 10

Não Afetado

Alpine

Afetados

edge

0.164.0-r0

Afetados

Origem: Este relatório foi gerado usando IA

Relacionado NixOS Vulnerabilidades:

CVE ID

Gravidade

Pontuação

Tecnologias

Nome do componente

Exploração do CISA KEV

Tem correção

Data de publicação

CVE-2026-103493HIGH8.1
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NãoSimOct 01, 2026
CVE-2026-103494MEDIUM6.6
  • YouTrack logoYouTrack
  • youtrack
NãoSimOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NãoSimOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NãoSimOct 01, 2026
CVE-2026-103495MEDIUM4.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NãoSimOct 01, 2026

Avaliação de vulnerabilidade gratuita

Compare sua postura de segurança na nuvem

Avalie suas práticas de segurança na nuvem em 9 domínios de segurança para comparar seu nível de risco e identificar lacunas em suas defesas.

Solicitar avaliação

Marque uma demonstração personalizada

Pronto para ver a Wiz em ação?

"A melhor experiência do usuário que eu já vi, fornece visibilidade total para cargas de trabalho na nuvem."
David EstlickCISO
"A Wiz fornece um único painel de vidro para ver o que está acontecendo em nossos ambientes de nuvem."
Adam FletcherDiretor de Segurança
"Sabemos que se a Wiz identifica algo como crítico, na verdade é."
Greg PoniatowskiChefe de Gerenciamento de Ameaças e Vulnerabilidades